{"id":"GHSA-477h-4r7f-fvrx","summary":"pbkdf2 rehashes long passwords on every iteration, enabling denial of service","details":"### Summary\nThis is the same bug as Django had (CVE-2013-1443).\n\n### Details\nA long password can cause a DoS because it is not using cached HMAC, length limits, or pre-hashing passwords longer than the block size of the hash function as per HMAC spec. This line of code hashes the full password each iteration: https://github.com/browserify/pbkdf2/blob/1c3b1f526b052a29b3b42120c9821895772df7e8/lib/sync.js#L60\n\nAlso see https://github.com/browserify/pbkdf2/issues/82\n\n### PoC\nThe first key will take a lot longer to generate when not using the native code and uses code from `/lib/sync.js` (ie when this if statement is true):\nhttps://github.com/browserify/pbkdf2/blob/1c3b1f526b052a29b3b42120c9821895772df7e8/index.js#L33-L37\n\n```js\nvar pbkdf2 = require('pbkdf2');\nvar createHash = require('create-hash');\nvar pw = \".\".repeat(1048576); // 1 MiB\n\nvar t0 = performance.now();\nvar key1 = pbkdf2.pbkdf2Sync(pw, \"salt\", 1000, 32, \"sha256\");\nvar t1 = performance.now();\npw = createHash('sha256').update(pw).digest(); // HMAC specification for keys larger than block size\nvar key2 = pbkdf2.pbkdf2Sync(pw, \"salt\", 1000, 32, \"sha256\");\nvar t2 = performance.now();\n\nconsole.log(\"First took:  \" + (t1 - t0));\nconsole.log(\"Second took: \" + (t2 - t1));\nconsole.log(\"Generated keys:\");\nconsole.log(key1);\nconsole.log(key2);\n```\n\n### Impact\nDoS","aliases":["CVE-2026-102414"],"modified":"2026-10-06T13:45:05.583424195Z","published":"2026-10-06T13:40:10Z","database_specific":{"nvd_published_at":"2026-09-29T04:17:55Z","cwe_ids":["CWE-400"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-10-06T13:40:10Z"},"references":[{"type":"WEB","url":"https://github.com/browserify/pbkdf2/security/advisories/GHSA-477h-4r7f-fvrx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102414"},{"type":"WEB","url":"https://github.com/browserify/pbkdf2/issues/82"},{"type":"WEB","url":"https://github.com/browserify/pbkdf2/commit/493d8d8ff437f680338bf7397398fda884ad462e"},{"type":"PACKAGE","url":"https://github.com/browserify/pbkdf2"}],"affected":[{"package":{"name":"pbkdf2","ecosystem":"npm","purl":"pkg:npm/pbkdf2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.1.7"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 3.1.6","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-477h-4r7f-fvrx/GHSA-477h-4r7f-fvrx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}]}